veraPDF-validation XXE Vulnerability: Early Warning
An XML External Entity Injection vulnerability in veraPDF-validation is under investigation. This vulnerability could allow a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery.
What happened
An XML External Entity Injection (XXE) vulnerability has been reported in veraPDF-validation, tracked as GHSA-36MM-W85J-3Q2J. This vulnerability appears to allow a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. The vulnerability affects all current versions of veraPDF-validation.
To assess your exposure, check if your systems are using veraPDF-validation. If so, it is recommended to upgrade to the latest version that includes the fix for this vulnerability. The primary source indicates that an upgrade is the recommended action to mitigate this risk.
For more detailed information, consult the primary source at https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-36mm-w85j-3q2j. The severity of this vulnerability is high, and it is crucial to take immediate action to protect your systems.
How 0Day mitigates this
verapdf-validation is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.